Skip to content

Evidence request lists

Colombia Data Protection Law (Law 1581 of 2012)

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Ley 1581: Data Protection Authority and Sanctions (Title VII)

CO-L1581-A19
Data Protection Authority (SIC)

The Superintendence of Industry and Commerce (SIC), through a Delegatura for Personal Data Protection, exercises oversight to ensure compliance with the law.

Artefacts an auditor will ask for
  • Awareness of SIC oversight + registration obligations
Where this commonly fails
  • No engagement with SIC requirements
CO-L1581-A21
Functions of the SIC

The SIC ensures compliance, processes consultations/complaints, orders measures, conducts investigations, imposes sanctions, administers the National Database Registry (RNBD) and issues instructions.

Artefacts an auditor will ask for
  • Procedures to respond to SIC investigations/orders
Where this commonly fails
  • No process for SIC requests
CO-L1581-A23
Sanctions

The SIC may impose fines up to 2,000 monthly minimum wages, suspension of activities, temporary/definitive closure of processing operations for sensitive-data violations.

Artefacts an auditor will ask for
  • Penalty-exposure awareness
  • Remediation tracking from SIC orders
Where this commonly fails
  • No awareness of sanction exposure

Ley 1581: Duties of Controllers and Processors (Title VI)

CO-L1581-A17
Duties of Controllers (Responsables)

Controllers must guarantee rights, obtain authorization, keep data accurate, ensure security, handle consultations/complaints, update/rectify/delete on request, inform of breaches to the SIC, and comply with SIC instructions.

Artefacts an auditor will ask for
  • Controller compliance program covering Art.17 duties
  • Security + breach-notification to SIC
Where this commonly fails
  • Controller duties not implemented
CO-L1581-A18
Duties of Processors (Encargados)

Processors must guarantee data security, handle consultations/complaints, apply the controller's policies, update/rectify/delete on instruction, and register databases as required; bound by a transmission contract.

Artefacts an auditor will ask for
  • Transmission contract with processors
  • Processor security + rights-handling evidence
Where this commonly fails
  • No transmission contract / processor duties undefined

Ley 1581: General Provisions and Principles (Titles I-II)

CO-L1581-A2
Scope of Application

Applies to personal data recorded in any database by public or private entities in Colombian territory or where Colombian law applies by international treaty, with stated exceptions (e.g. domestic/personal, journalistic, intelligence, financial-credit databases under their own regimes).

Artefacts an auditor will ask for
  • Determination that processing is within Ley 1581 scope
  • Mapping of any exempt databases
Where this commonly fails
  • Scope/exemptions not assessed
CO-L1581-A3
Definitions

Defines key terms: Titular (data subject), Tratamiento (processing), Responsable (controller), Encargado (processor), Autorizacion (authorization), Base de Datos, Dato personal, Dato publico/privado/semiprivado.

Artefacts an auditor will ask for
  • Data inventory using Ley 1581 categories
  • Controller/processor role mapping
Where this commonly fails
  • Roles (Responsable/Encargado) not assigned
CO-L1581-A4-ACCESO
Principle of Restricted Access and Circulation

Processing is limited by the nature of the data; personal data (except public data) may not be available on the Internet or mass media unless access is technically controllable for authorized parties.

Artefacts an auditor will ask for
  • Controls preventing public exposure of non-public personal data
Where this commonly fails
  • Personal data publicly accessible online
CO-L1581-A4-CONFID
Principle of Confidentiality

All persons involved in processing non-public data must guarantee confidentiality, even after the relationship ends.

Artefacts an auditor will ask for
  • Confidentiality undertakings for personnel/processors
Where this commonly fails
  • No confidentiality obligations
CO-L1581-A4-FINALIDAD
Principle of Purpose

Processing must serve a legitimate purpose under the Constitution and law, which must be informed to the data subject.

Artefacts an auditor will ask for
  • Documented legitimate purpose per processing, communicated to data subjects
Where this commonly fails
  • Purpose undefined or not informed
CO-L1581-A4-LEGALIDAD
Principle of Legality

Processing is a regulated activity that must comply with Ley 1581 and its implementing rules.

Artefacts an auditor will ask for
  • Lawful-processing policy referencing Ley 1581 + Decreto 1377/2013
Where this commonly fails
  • Processing without a legal framework basis
CO-L1581-A4-LIBERTAD
Principle of Freedom (Consent)

Processing requires the prior, express and informed consent of the data subject; data may not be obtained or disclosed without authorization or a legal/judicial mandate.

Artefacts an auditor will ask for
  • Prior express informed authorization records
Where this commonly fails
  • Processing without prior authorization
CO-L1581-A4-SEGURIDAD
Principle of Security

Data must be managed with the technical, human and administrative measures necessary to secure records against adulteration, loss, unauthorized or fraudulent access.

Artefacts an auditor will ask for
  • Technical/administrative security measures for personal data
Where this commonly fails
  • No security measures
CO-L1581-A4-TRANSPARENCIA
Principle of Transparency

The data subject has the right to obtain, at any time and without restriction, information about the existence of data concerning them.

Artefacts an auditor will ask for
  • Mechanism for data subjects to learn what data is held
Where this commonly fails
  • No transparency mechanism
CO-L1581-A4-VERACIDAD
Principle of Veracity and Quality

Data must be truthful, complete, accurate, up to date, verifiable and comprehensible; partial, incomplete or misleading data processing is prohibited.

Artefacts an auditor will ask for
  • Data accuracy/update procedures
Where this commonly fails
  • Inaccurate or partial data processed

Ley 1581: Registry, International Transfers and BCRs

CO-L1581-A25
National Database Registry (RNBD)

Controllers must register their databases in the National Database Registry (Registro Nacional de Bases de Datos) administered by the SIC.

Artefacts an auditor will ask for
  • RNBD registration records for all databases
Where this commonly fails
  • Databases not registered in the RNBD
CO-L1581-A26
Prohibition on International Transfers

Transfer of personal data to countries not providing adequate protection levels is prohibited, except: subject authorization; medical/health exchange; bank/stock transfers; treaties; legal/judicial cooperation; or SIC-declared adequacy.

Artefacts an auditor will ask for
  • Transfer adequacy assessment / SIC declaration / subject authorization per recipient
Where this commonly fails
  • Transfers to non-adequate countries without an Art.26 basis
CO-L1581-A27
Binding Corporate Rules

Transfers and transmissions within corporate groups may rely on binding corporate rules (normas corporativas vinculantes) authorized by the SIC.

Artefacts an auditor will ask for
  • Approved binding corporate rules where relied upon
Where this commonly fails
  • Intra-group transfers without an authorized mechanism

Ley 1581: Rights and Conditions of Lawful Processing (Titles IV-V)

CO-L1581-A10
Cases Not Requiring Authorization

Authorization is not required for: information required by a public/administrative entity in legal exercise or by court order; public-nature data; medical/health emergencies; authorized historical/statistical/scientific processing; data related to civil registry.

Artefacts an auditor will ask for
  • Assessment of Art.10 exceptions relied upon
Where this commonly fails
  • Exception claimed without basis
CO-L1581-A12
Duty to Inform the Data Subject (Privacy Notice)

At or before collection the controller must inform the subject of the processing and its purpose, their rights, and the identity/contact of the controller (privacy notice / aviso de privacidad).

Artefacts an auditor will ask for
  • Privacy notice (aviso de privacidad) covering Art.12 elements
Where this commonly fails
  • No privacy notice at collection
CO-L1581-A13
Persons to Whom Information May Be Disclosed

Personal data may be supplied only to the data subject/assignees, entities with legal/judicial authority, and third parties authorized by the subject or law.

Artefacts an auditor will ask for
  • Disclosure-authorization controls
Where this commonly fails
  • Data disclosed to unauthorized parties
CO-L1581-A14
Consultations (Access Requests)

Data subjects (or assignees) may consult their personal data held by a controller/processor; the consultation must be answered within ten (10) business days (extendable by five).

Artefacts an auditor will ask for
  • Consultation handling procedure + timeliness logs (10 business days)
Where this commonly fails
  • Consultations not answered within deadline
CO-L1581-A15
Complaints (Reclamos)

Data subjects may file complaints to correct, update, delete data or for breach of the law; complaints must be handled within fifteen (15) business days (extendable by eight).

Artefacts an auditor will ask for
  • Complaint (reclamo) handling procedure + timeliness logs (15 business days)
Where this commonly fails
  • Complaints not handled within deadline
CO-L1581-A8
Data Subject Rights (Habeas Data)

Data subjects may: know, update and rectify their data; request proof of authorization; be informed of the use of their data; lodge complaints with the SIC; revoke authorization and/or request deletion when processing breaches the law or constitution; and access their data free of charge.

Artefacts an auditor will ask for
  • Procedure for know/update/rectify/revoke/delete requests
  • Free-of-charge access mechanism
Where this commonly fails
  • Rights requests not supported
  • Revocation/deletion not honored
CO-L1581-A9
Authorization of the Data Subject

Processing requires prior, express and informed authorization of the data subject (except Art.10 cases), obtained by any means that can later be evidenced.

Artefacts an auditor will ask for
  • Authorization capture with evidentiary proof
Where this commonly fails
  • No demonstrable authorization

Ley 1581: Special Categories of Data (Title III)

CO-L1581-A5
Sensitive Data Definition

Sensitive data affects the data subject's intimacy or whose misuse may cause discrimination: racial/ethnic origin, political orientation, religious/philosophical convictions, union/social/human-rights membership, health, sex life, and biometric data.

Artefacts an auditor will ask for
  • Inventory flagging sensitive categories per Art.5
Where this commonly fails
  • Sensitive categories not identified
CO-L1581-A6
Processing of Sensitive Data

Processing sensitive data is prohibited except: explicit authorization; vital interest of an incapacitated subject; legitimate activities of a non-profit (political/religious/union) for its members; judicial proceedings; or historical/statistical/scientific purpose with de-identification measures.

Artefacts an auditor will ask for
  • Explicit authorization for sensitive data
  • Exception basis records
  • De-identification for research use
Where this commonly fails
  • Sensitive data processed without explicit authorization or valid exception
CO-L1581-A7
Children's and Adolescents' Data

Processing must respect the prevailing rights of children and adolescents; processing their data is proscribed except public-nature data; the State and educational entities must inform guardians of risks.

Artefacts an auditor will ask for
  • Controls/age-gating for minors' data
  • Guardian information measures
Where this commonly fails
  • Minors' data processed without safeguards
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colombia Data Protection Law (Law 1581 of 2012) framework page.